
Cling Botnet Abuses STUN Servers for Covert Control
Nozomi Networks and Fortinet report that Cling malware exploits router and DVR flaws, then hides botnet commands in ordinary STUN traffic.
Security researchers have observed attempts to exploit a now-patched critical flaw in the Realtek Jungle software development kit (SDK) to install a botnet called Cling. A botnet is a network of hijacked internet-connected devices that an operator controls remotely. The Realtek Jungle SDK is a set of tools that device makers use to build firmware for routers and other network equipment. Nozomi Networks, an operational technology security company, said in a report published last week that Cling is notable because it reuses ordinary STUN behavior as a practical command-and-control (C2) channel, rather than introducing a new propagation technique. The result, according to Nozomi, is a botnet whose traffic can look like legitimate NAT traversal activity while still supporting propagation, proxying, tunneling and denial-of-service commands. The company observed a spike in attempts to exploit CVE-2021-35394, a critical remote code execution flaw with a CVSS score of 9.8, starting around September 5, 2026, and a subset of that activity delivered Cling.
An analysis of the Cling sample found embedded exploit logic for several command injection and remote code execution vulnerabilities in routers and digital video recorders from multiple vendors. The listed flaws are CVE-2014-8361 in Realtek SDK, CVE-2016-10372 in Eir D1000 routers, CVE-2016-20016 in MVPower CCTV DVRs, CVE-2023-26801 in LB-LINK routers, CVE-2023-41011 in FiberHome SR1041F and China Mobile HG6543C4 routers, CVE-2024-3721 in TBK DVRs, and CVE-2025-34037 in Linksys devices. To make sure only one copy runs, Cling binds a socket with SO_REUSEADDR to port 33957 and exits cleanly if that fails. The malware copies itself to /root/.cling and /usr/local/bin/.cling, then appends both executable paths to /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot, which achieves persistence on SysV and BusyBox init systems. As an alternative persistence method, Cling locates the wget binary on the infected system, moves the original to another location, and replaces it with itself, so the malware is executed whenever a legitimate process calls the wget command.
Cling's most distinctive feature is how it abuses STUN traffic. STUN, short for Session Traversal Utilities for Network Address Translation, is a standard protocol that helps devices behind a NAT or firewall set up peer-to-peer real-time communications, such as voice or video calls. Cling follows a four-step process for C2. First, it sends a STUN Binding Request to a hard-coded list of 13 STUN servers roughly every 5 seconds, using a transaction ID set to all zeros instead of the random value the specification requires. Second, it records the externally observed ports returned by those servers in Binding Success Response messages that contain the device's public IP address and associated port numbers. Third, it sends a custom registration message, a UDP datagram, to each server with the mapped ports and a tag showing how the device was infected, such as realtek.selfrep or selfrep.router. Fourth, it polls for UDP packets that encode operator commands in the STUN transaction ID field. From a network monitoring perspective, Nozomi Networks said, this activity looks like an innocuous interaction with STUN servers.
The registration messages do not conform to the STUN protocol definition, so legitimate STUN servers normally drop the packet. However, one of the 13 servers, at 145.249.115[.]184, returned an all-zero transaction ID instead of echoing the transaction ID of the original Binding Request. Nozomi said this unusual behavior suggests the server is tailored to the bot's own STUN traffic and is used to send operator-issued commands by embedding them in the transaction ID field. Those commands allow the attacker to recursively scan and spread the botnet in a worm-like fashion, spawn or stop a TCP tunnel, launch or stop a proxy, and run a denial-of-service attack against a target for a specified duration. Among the flooding targets observed are 112.151.157[.]222:8080, a South Korean ISP; 192.170.240[.]137:53, a University of Chicago cluster; and two Minecraft servers at 23.81.40[.]193:25565 and 147.185.221[.]129:25565. The most interesting part, Nozomi explained, is that packets carrying operator commands originate from 74.125.250[.]129, an IP address that stun.l.google.com resolves to. The operator is not just hiding commands inside a STUN-looking packet, but making those commands appear as legitimate replies from one of the most recognizable STUN services on the internet.
In an update published on October 5, 2026, Fortinet FortiGuard Labs described the same malware as exploiting unpatched vulnerabilities in internet-facing devices to establish a persistent foothold, and named it ClingSTUN. Fortinet said the malware has been observed gaining initial access through a wide set of additional command injection flaws, including CVE-2019-7256 in Linear; CVE-2019-17621, CVE-2022-37055, CVE-2024-23624, CVE-2024-10914, CVE-2024-10915, and CVE-2024-23625 in D-Link; CVE-2021-36380 in Sunhillo SureLine; CVE-2022-26289, CVE-2022-35555, CVE-2024-32281, CVE-2024-32292, CVE-2024-32314, CVE-2024-35340, and CVE-2024-46048 in Tenda; CVE-2022-36553 in Hytec Inter HWL-2511-SS routers; CVE-2023-1389 in TP-Link; CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure and Policy Secure; CVE-2024-7029 in AVTECH; CVE-2025-34035 in EnGenius; CVE-2025-67038 in Lantronix EDS5000; and CVE-2026-36356 in MeiG. Like other botnet families, these attacks use shell script downloaders to fetch malware payloads for several Linux architectures, including ARM, Intel 80386, MIPS R3000, PowerPC, and AMD X86-64. Once launched, Cling is equipped to terminate competing malware, set up persistence, enable remote command execution, and self-propagate. For self-propagation, Cling hard-codes exploits for seven vulnerabilities: CVE-2014-8361 in Realtek, CVE-2016-20016 in MVPower, CVE-2023-26801 in LB-LINK, CVE-2023-41011 in China Mobile, CVE-2024-3721 in TBK, CVE-2025-34037 in Linksys, and CVE-2026-87827 in KGUARD DVRs. Fortinet described ClingSTUN as a backconnect proxy backdoor that turns infected systems into remotely controlled proxy nodes. It abuses public STUN infrastructure to discover externally mapped IP addresses and ports, maintain NAT bindings, and improve connectivity between compromised hosts and remote operators. Because many of the STUN servers it contacts are legitimate public services, Fortinet said, the resulting traffic easily blends with normal VoIP and WebRTC communications.
Because Cling can turn compromised devices into proxy exits and denial-of-service launch pads, website operators should treat router and DVR security as part of their overall defence. Keeping firmware current, replacing unsupported hardware, and isolating smart devices are practical first steps. For readers who run websites, AEU Hosting (https://albhosting.eu) offers managed WordPress hosting with end-to-end security, which
How to Protect Yourself
- Update the software inside your router, security cameras and DVR to the latest version, and turn on automatic updates if the device offers it.
- Change the default admin password on your router and any security cameras or recorders to a long unique passphrase.
- If you do not need to reach your router or camera from outside your home, turn off remote access in the device settings.
- Check the manufacturer's support page for your router or DVR model and install any security patches marked critical.
- Create a separate Wi-Fi network for smart devices and guests, so an infected camera or DVR cannot easily reach your main computers and phones.
- Replace very old routers, cameras or recorders that no longer get security updates.
Vulnerabilities & Fixes
- CVE-2014-8361 Realtek SDK remote code execution flaw included in Cling's embedded exploit set. View the fix & details →
- CVE-2016-10372 Eir D1000 router remote code execution flaw included in Cling's embedded exploit set. View the fix & details →
- CVE-2016-20016 MVPower CCTV DVR remote code execution flaw included in Cling's embedded exploit set and self-propagation list. View the fix & details →
- CVE-2019-17621 D-Link command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2019-7256 Linear command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2021-35394 Critical remote code execution flaw in Realtek Jungle SDK, now patched; exploited to deliver Cling botnet. View the fix & details →
- CVE-2021-36380 Sunhillo SureLine command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2022-26289 Tenda command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2022-35555 Tenda command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2022-36553 Hytec Inter HWL-2511-SS router command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2022-37055 D-Link command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2023-1389 TP-Link command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2023-26801 LB-LINK router remote code execution flaw included in Cling's embedded exploit set and self-propagation list. View the fix & details →
- CVE-2023-41011 FiberHome SR1041F and China Mobile HG6543C4 router remote code execution flaw included in Cling's embedded exploit set and self-propagation list. View the fix & details →
- CVE-2023-46805 Ivanti Connect Secure and Policy Secure command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-10914 D-Link command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-10915 D-Link command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-21887 Ivanti Connect Secure and Policy Secure command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-23624 D-Link command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-23625 D-Link command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-32281 Tenda command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-32292 Tenda command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-32314 Tenda command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-35340 Tenda command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-3721 TBK DVR remote code execution flaw included in Cling's embedded exploit set and self-propagation list. View the fix & details →
- CVE-2024-46048 Tenda command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2024-7029 AVTECH command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2025-34035 EnGenius command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2025-34037 Linksys remote code execution flaw included in Cling's embedded exploit set and self-propagation list. View the fix & details →
- CVE-2025-67038 Lantronix EDS5000 command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2026-36356 MeiG command injection flaw used by ClingSTUN for initial access. View the fix & details →
- CVE-2026-87827 KGUARD DVR remote code execution flaw in Cling's self-propagation list. View the fix & details →
Terms Explained
- Botnet A group of hijacked internet-connected devices that a criminal controls remotely to send spam, attack websites or hide traffic.
- C2 Short for command-and-control, the communication channel an attacker uses to send instructions to malware on infected devices.
- NAT Network Address Translation, a technique routers use to share one public internet address among many devices on a home or office network.
- STUN Session Traversal Utilities for NAT, a standard way for devices behind a router to discover their public internet address and open paths for real-time calls.
- RCE Remote code execution, a type of security hole that lets an attacker run their own commands on a device from far away.
- DoS Denial-of-service, an attack that floods a target with traffic or requests so it becomes slow or unreachable.
- Proxy A middle computer that forwards internet traffic, which can hide where the traffic really comes from.
- Transaction ID A short value in a network request used to match it to the correct reply.